• flying_sheep@lemmy.ml
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    4 days ago

    That’s not how that works.

    • when you use distribution-provided packages, you trust the distribution maintainers
    • when you use the AUR you trust the upstream project and check the PKGBUILD because the maintainer can change

    In some cases, upstream also maintains the AUR package, in which case you can probably trust that it’ll not be abandoned